SEC Cyber Disclosure Rules
The SEC Cyber Disclosure Rules are U.S. Securities and Exchange Commission requirements that direct public companies to tell investors about serious cybersecurity incidents and about how they manage cyber risk. Companies must report a cybersecurity incident once they judge it to be material, and must also describe their cyber risk management and governance in their annual reports. The rules aim to make such disclosures more transparent, consistent, and timely across companies.
A set of rules adopted by the U.S. Securities and Exchange Commission in 2023 (effective December 2023) to standardize and enhance registrant disclosures regarding cybersecurity. The incident-disclosure component requires companies to disclose material cybersecurity incidents on Form 8-K, typically within four business days of determining that an incident is material; the trigger is the materiality determination rather than the date of discovery or occurrence. The periodic-disclosure component requires annual Form 10-K disclosures describing the company's processes for assessing, identifying, and managing material cybersecurity risks, along with related strategy and governance information, including board and management oversight. These rules govern what and when public registrants must disclose to investors; they are a securities-disclosure obligation and do not themselves prescribe specific technical security controls, mandate a particular cybersecurity framework, or confer any certification or assurance of a company's security posture. Scope is limited to SEC registrants subject to U.S. federal securities reporting; requirements and enforcement expectations may differ for foreign private issuers, smaller reporting companies, and IPO registrants, and this rule set is distinct from cyber-disclosure or breach-notification regimes in other jurisdictions.
Why it matters
For third-party and supply chain risk professionals, the SEC Cyber Disclosure Rules change the information environment around the public companies they rely on as suppliers, service providers, and business partners. Because the rules require registrants to disclose material cybersecurity incidents on Form 8-K and to describe their cyber risk management, strategy, and governance in annual 10-K filings, they create a more transparent, consistent, and timely stream of publicly available signals that can inform vendor due diligence and ongoing monitoring. A supplier's 8-K incident disclosure or its annual description of cyber governance can supplement, but does not replace, direct assessment through questionnaires or contractual reporting arrangements.
The rules also carry a subtle but important limitation for risk teams: the incident-disclosure trigger is the company's own materiality determination, not the date an incident was discovered or occurred. This means disclosures are shaped by each registrant's judgment and are oriented toward investors' interests, so they may not surface incidents a customer or partner would consider operationally significant, and they may not capture the timing that matters most for supply chain response. The 10-K disclosures describe processes and governance rather than certifying security posture, so they should be read as context, not assurance.
Because the scope is limited to SEC registrants subject to U.S. federal securities reporting, coverage is uneven across a supply base. Privately held suppliers, and vendors based outside the United States, are not captured in the same way, and requirements and enforcement expectations may differ for foreign private issuers, smaller reporting companies, and IPO registrants. Risk professionals should therefore treat these disclosures as one input among several rather than a comprehensive early-warning system.
Who it's relevant to
Inside SEC Cyber Disclosure Rules
Common questions
Answers to the questions practitioners most commonly ask about SEC Cyber Disclosure Rules.